师资队伍
bob777@sjtu.edu.cn 闵行区东川路800号软件大楼5209 个人主页

陈力波

高级工程师

网络空间安全学院创新实践教学研究室副主任(高级工程师/硕士生导师),毕业于清华大学网络与信息安全实验室(NISL),是著名安全战队“Blue- Lotus”蓝莲花的创始成员,具备多年网络安全攻防经验。研究方向为软件与系统安全、物联网安全以及AI安全,在国内外重要学术会议和期刊上发表论文三十余篇,入选军队高层次科技创新人才和国家广电总局首批网络安全专家。近年来在漏洞挖掘领域,取得了多项国际前沿的安全研究成果,以第一作者发表在多个网络安全顶级会议和期刊(如USENIX Security 2021、ACM CCS 2022、IEEE TDSC等),得到国内外知名厂商致谢(如中国移动、CISCO、D-Link、NETGEAR、TP-Link等)及上百个CVE、CNVD漏洞编号,并带领上海交大0ops战队多次在知名漏洞破解大赛上获奖(例如,中国网络安全年会--智能破解挑战赛优胜奖、“天府杯”2018 设备破解赛优胜奖、“天府杯”2019最佳原创漏洞复现奖、2020年“极棒漏洞挑战赛”的破解成功奖和最具人气奖、2021年极棒G-TOP年度优秀极客、2023年“天网杯”安全漏洞挖掘挑战赛冠军等),编写了《Metasploit渗透测试魔鬼训练营》、《Python黑帽子:黑客与渗透测试编程之道》、《Web安全之逻辑漏洞检测入门》等多部网络安全领域畅销书籍。



  • 研究兴趣
  • 教育背景
  • 工作经验
  • 教授课程
  • 论文发表
  • 项目资助
  • 获奖信息
  • 学术服务
软件与系统安全,物联网安全,区块链安全,人工智能安全

本科生:系统安全攻防实践、工科创II--CTF和漏洞挖掘实战、物联网安全与漏洞挖掘利用
研究生:漏洞挖掘与分析



1、Vulnerability-oriented Testing for RESTful APIs.
Wenlong Du, Jian Li, Yanhao Wang, Libo Chen*, Ruijie Zhao, Junmin Zhu, Zhengguang Han, Yijun Wang, and Zhi Xue.
In Proceedings of the 33th USENIX Security Symposium (USENIX Security 2024).

2、Code is not Natural Language: Unlock the Power of Semantics-Oriented Graph Representation for Binary Code Similarity Detection.
Haojie He, Xingwei Lin, Ziang Weng, Ruijie Zhao, Shuitao Gan, Libo Chen*, Yuede Ji, Jiashui Wang, and Zhi Xue.
In Proceedings of the 33th USENIX Security Symposium (USENIX Security 2024).

3、ActiveDaemon: Unconscious DNN Dormancy and Waking Up via User-specific Invisible Token.
Ge Ren, Gaolei Li, Shenghong Li, Libo Chen*, and Kui Ren.
Network and Distributed Systems Security (NDSS) Symposium 2024.

4、SaTC: Shared-Keyword Aware Taint Checking for Detecting Bugs in Embedded Systems.
Libo Chen, Yanhao Wang, Jiaqi Linghu, Qinsheng Hou, Quanpu Cai, Shanqing Guo, and Zhi Xue.
IEEE Transactions on Dependable and Secure Computing, Early Access, doi: 10.1109/TDSC.2023.3307430.

5、GeeSolver: A Generic, Efficient, and Effortless Solver with Self-Supervised Learning for Breaking Text Captchas.
Ruijie Zhao, Xianwen Deng, Yanhao Wang, Zhicong Yan, Zhengguang Han, Libo Chen, Zhi Xue, and Yijun Wang.
IEEE Symposium on Security and Privacy (IEEE S&P 2023).


6、VD-Guard: DMA Guided Fuzzing for Hypervisor Virtual Device.

Yuwei Liu, Siqi Chen, Yuchong Xie, Yanhao Wang, Libo Chen*, Bin Wang, Yingming Zeng, Zhi Xue, and Purui Su

IEEE/ACM International Conference on Automated Software Engineering (ASE 2023)


7、Subdomain Protection is Needed: An SPF and DMARC-based Empirical Measurement Study and Proactive Solution of Email Security.

Han Zhang, Dengke Mi, Libo Chen*, Ming Liu, Yong Shi, and Zhi Xue

42nd International Symposium on Reliable Distributed Systems (SRDS 2023)


8、SFuzz: Slice-based Fuzzing for Real-Time Operating Systems.
Libo Chen, Quanpu Cai, Zhenbang Ma, Yanhao Wang, Hong Hu, Minghang Shen, Yue Liu, Shanqing Guo, Haixin Duan, Kaida Jiang, and Zhi Xue.
In Proceedings of the 29th ACM Conference on Computer and Communications Security (ACM CCS 2022).

9、3E-Solver: An Effortless, Easy-to-Update, and End-to-End Solver with Semi-Supervised Learning for Breaking Text-Based Captchas.
Xianwen Deng, Ruijie Zhao, Yanhao Wang, Libo Chen, Yijun Wang, and Zhi Xue. 
In Proceedings of the 31st International Joint Conference on Artificial Intelligence (IJCAI 2022).

10、SEAF: A Scalable, Efficient, and Application-independent Framework for container security detection.
Libo Chen, Yihang Xia, Zhenbang Ma, Ruijie Zhao, Yanhao Wang, Yue Liu, Wenqi Sun, Zhi Xue.
Journal of Information Security and Applications, Volume 71, 2022, 103351, ISSN 2214-2126, doi: 10.1016/j.jisa.2022.103351.

11、Flow Sequence-Based Anonymity Network Traffic Identification with Residual Graph Convolutional Networks.
Ruijie Zhao, Xianwen Deng, Yanhao Wang, Libo Chen, Ming Liu, Zhi Xue, and Yijun Wang.
In Proceedings of the 30th IEEE/ACM International Symposium on Quality of Service (IWQoS 2022).

12、Sharing More and Checking Less: Leveraging Common Input Keywords to Detect Bugs in Embedded Systems.
Libo Chen, Yanhao Wang, Quanpu Cai, Yunfan Zhan, Hong Hu, Jiaqi Linghu, Qinsheng Hou, Chao Zhang, Haixin Duan, and Zhi Xue.
In Proceedings of the 30th USENIX Security Symposium (USENIX Security 2021).

1、上海市“科技创新行动计划”高新技术领域项目--工业环境下5G安全攻防关键技术研究

2、教育部产学合作协同育人项目--教学内容和课程体系改革

3、公安部重点实验室开放课题针对泛在互联终端的脆弱性自动化挖掘

Copyright © 2017 - 2019 上海交通大学网络空间安全学院 沪ICP备05052060号